VYPR

Vendor CVEs

PraisonAI

All CVEs

83 total · sorted by risk
  • CVE-2026-47411MedJul 21, 2026
    risk 0.35cvss 6.5epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is gated only by…

  • CVE-2026-56074MedJun 18, 2026
    risk 0.29cvss 5.5epss 0.00

    PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate…

  • CVE-2026-57128MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handling /publish, /events, or /info requests. A network client that can reach the…

  • CVE-2026-61446HigJul 15, 2026
    risk 0.00cvss 8.4epss 0.00

    PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and user-home .praisonai/plugins/ directories using importlib spec_from_file_location() and…

  • CVE-2026-61443HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.01

    PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those…

  • CVE-2026-61440MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and…

  • CVE-2026-61438HigJul 15, 2026
    risk 0.00cvss 7.3epss 0.00

    PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system()…

  • CVE-2026-61436HigJul 15, 2026
    risk 0.00cvss 8.6epss 0.01

    PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender…

  • CVE-2026-61435HigJul 15, 2026
    risk 0.00cvss 8.2epss 0.01

    PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding…

  • CVE-2026-61433HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the…

  • CVE-2026-61430HigJul 15, 2026
    risk 0.00cvss 8.5epss 0.00

    PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal…

  • CVE-2026-61427HigJul 15, 2026
    risk 0.00cvss 7.3epss 0.00

    PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer checks when an API key is configured. When an operator runs 'praisonai mcp serve…

  • CVE-2026-60087MedJul 15, 2026
    risk 0.00cvss 6.1epss 0.00

    PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write…

  • CVE-2026-60085HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute…

  • CVE-2026-61447CriJul 11, 2026
    risk 0.00cvss 10.0epss 0.02

    PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to…

  • CVE-2026-61445CriJul 11, 2026
    risk 0.00cvss 9.9epss 0.01

    PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to…

  • CVE-2026-61442HigJul 11, 2026
    risk 0.00cvss 7.1epss 0.00

    PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created records; for projects, a member can…

  • CVE-2026-61439HigJul 11, 2026
    risk 0.00cvss 7.5epss 0.00

    PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction…

  • CVE-2026-61429HigJul 11, 2026
    risk 0.00cvss 8.5epss 0.00

    PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after…

  • CVE-2026-61428HigJul 11, 2026
    risk 0.00cvss 7.3epss 0.00

    PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content…

  • CVE-2026-61426HigJul 11, 2026
    risk 0.00cvss 8.6epss 0.00

    PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents…

  • CVE-2026-60090CriJul 11, 2026
    risk 0.00cvss 9.8epss 0.01

    PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not…

  • CVE-2026-60088MedJul 11, 2026
    risk 0.00cvss 5.5epss 0.00

    PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate…

  • CVE-2026-61444CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.01

    PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs…

  • CVE-2026-61441MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who…

  • CVE-2026-61437HigJul 10, 2026
    risk 0.00cvss 7.8epss 0.00

    PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the…

  • CVE-2026-61434HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.01

    PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to…

  • CVE-2026-61432MedJul 10, 2026
    risk 0.00cvss 5.7epss 0.00

    PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor…

  • CVE-2026-61431MedJul 10, 2026
    risk 0.00cvss 5.5epss 0.00

    PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute paths or parent directory traversal sequences to read arbitrary files outside the…

  • CVE-2026-60091HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.00

    PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach…

  • CVE-2026-60089MedJul 10, 2026
    risk 0.00cvss 5.5epss 0.00

    PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an…

  • CVE-2026-60086MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt…

  • CVE-2026-58653MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation…

Page 2 of 2